Tastyer
Privacy Policy
Last updated: September 23, 2026
1. Introduction
Tastyer (“we”, “our”, “us”) respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use the Tastyer mobile application (“App”) and the website tastyer.com, including the web app (“Website”).
2. Data We Collect
Account Information
- Email address
- Username (auto-generated, editable)
- Password (hashed, never stored in plain text)
- Social sign-in identifiers (Google ID, Apple ID) if you use social login
- Language preference
Recipe Data
- Recipe URLs you submit for transformation
- Original and transformed recipe ingredients
- Nutritional macro estimates (AI-generated)
- Your recipe ratings and view history
Grocery Lists
- Items added to your grocery list from recipes
- Checked/unchecked status of grocery items
Food & Meal Data
- The meals you log — foods, portions, meal type, and the date and time you logged them
- Barcodes you scan, text or speech you use to search for a food, and the nutrition labels you photograph
- Corrections you make to a food match ("this food, not that one"). These are stored as anonymous signals that improve the shared food catalog for everyone; they are not published with your name or account attached.
Photos
- Photos you take of a meal or a nutrition label. These are uploaded to our servers so the food in them can be recognised, and are stored against the meal you attached them to. We never access your photo library — you choose each individual image.
Health & Fitness Data
- From Apple Health, only if you grant permission: your step count and active energy burned. Tastyer only ever reads from Apple Health — it never writes anything back.
- Body measurements you enter yourself, such as weight and height, plus date of birth and biological sex if you choose to provide them
- Calorie and macro targets we calculate for you from the above
Health and fitness data is used solely to show your own activity and to calibrate your calorie and macro targets. We do not sell it, we do not use it for advertising or marketing, and we do not share it with data brokers or with any third party for their own purposes. Data read from Apple Health is never used for advertising or shared with third parties under any circumstances.
Product Usage Events
To understand which parts of Tastyer work and where people get stuck, the App and the Website record a small set of first-party product events — for example that a page was viewed, a recipe was transformed, the subscription screen was shown, or an App Store link was tapped. Each event contains:
- the event name and the time it happened
- a random identifier created on your device (in the App, a random ID; on the Website, the
tst_aidcookie described in section 8) - the platform (iOS or web), your language and, in the App, the app version
- a few details about the event itself, such as which page or button, or how long a recipe transform took
When you are signed in, events are linked to your account. Events recorded on a device before you sign up or log in are linked to your account from that moment. We collect these events ourselves and store them on our own servers: they are never sold, never shared with advertising networks, and not passed to any third party for its own purposes. We keep them for 13 months, after which they are deleted. We rely on our legitimate interest in understanding and improving Tastyer; you can object at any time by emailing privacy@tastyer.com.
Install & Campaign Attribution
- Apple Search Ads:the first time you open the App, it asks iOS for an attribution token through Apple's AdServices framework and sends it to our server. Our server asks Apple whether the install came from an Apple Search Ads campaign and, if so, which campaign, ad group and keyword. This is campaign-level information: it contains no advertising identifier (IDFA), the App does not use App Tracking Transparency, and we do not combine it with data from other companies.
- Website:on your first visit we note how you arrived — the campaign tags in the link (“utm” parameters), the website that referred you (without its query string) and the page you landed on — in the
tst_ftcookie. If you create an account or log in within 30 days, we save this first-visit information with your account once, so we can see which campaigns and pages bring people to Tastyer.
Subscriptions & Payments
- In the App: Tastyer Pro is bought through the App Store. Apple processes the payment; we never see your card or bank details. RevenueCat manages App Store subscriptions on our behalf and tells us your subscription status.
- On the Website:Tastyer Pro is paid through Mollie B.V. (Amsterdam), a licensed payment service provider. You enter your payment details on Mollie's checkout page, not ours, and we never see or store your full card or bank account details.
- We store what we need to provide Pro: which plan you have, where you bought it (App Store or web), its status, when it renews or ends, and the purchase and payment references from Apple, RevenueCat or Mollie.
Password Reset
- If you ask to reset your password, we email a link to the address on your account. The link works once and expires after one hour. We tell everyone who asks the same thing, so the form never reveals whether an email address has an account.
Technical Data
- Device language (via Accept-Language header)
- API request metadata (timestamps, IP addresses in server logs). IP addresses are also used briefly for rate limiting and to prevent abuse.
3. How We Use Your Data
- Provide the service: Transform recipes, maintain your library, generate grocery lists
- Authentication: Verify your identity and manage your account
- Improvement: Understand usage patterns to improve the App and the Website, using the product events described above
- Measurement: See which campaigns, pages and store links bring people to Tastyer, at campaign level
- Subscriptions: Provide Tastyer Pro, process renewals and cancellations, and meet our accounting and tax obligations
- Communication: Send service-related notifications (e.g., account security, password reset emails, and notice of price changes to your subscription)
4. Third-Party Services
We share limited data with the following third-party services:
- OpenAI:Recipe ingredient data is sent to OpenAI's API for AI-powered transformation. No personal identifiers are included in these requests.
- Google Sign-In: If you sign in with Google, we receive your Google ID and email. See Google's Privacy Policy.
- Apple Sign-In: If you sign in with Apple, we receive your Apple ID. See Apple's Privacy Policy.
- Pexels: Recipe titles may be sent to Pexels for image search. No personal data is shared.
- Apple (App Store and Apple Search Ads): Apple processes App Store purchases and tells us, at campaign level, whether an install came from an Apple Search Ads campaign. See Apple's Privacy Policy.
- RevenueCat: Manages App Store subscriptions for us. It receives your Tastyer account ID and your App Store purchase details to confirm your subscription status. See RevenueCat's Privacy Policy.
- Mollie B.V.: Processes web payments for Tastyer Pro. It receives your name (or username), email address, Tastyer account ID, the plan you chose and the payment details you enter on its checkout page. See Mollie's Privacy Statement.
- Email delivery: Service emails such as password reset links are sent through an email delivery provider that processes your email address only to deliver the message.
5. Data Storage & Security
- Data is stored on secure servers within the European Union
- Passwords are hashed using bcrypt
- API communication is encrypted via TLS (HTTPS)
- Authentication uses JWT tokens (short-lived access tokens + refresh tokens)
- We implement rate limiting and security headers to protect against common attacks
6. Data Retention
We retain your data for as long as your account is active. When you delete your account, your personal data is permanently removed from our systems within 30 days. Server logs containing IP addresses are retained for up to 90 days for security purposes.
- Product usage events: 13 months, then deleted.
- First-visit attribution: 30 days in your browser; once saved with your account, for as long as the account exists.
- Password reset links: one hour, or until used.
- Subscription and payment records: for as long as your account exists, and after that only as long as tax and accounting law requires (in the Netherlands, seven years).
7. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Delete your account and associated data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing of your personal data
To exercise these rights, contact us at privacy@tastyer.com.
8. Cookies & Tracking
The Tastyer App does not use cookies or third-party advertising trackers. We do not serve advertisements. We do not share your data with data brokers or advertising networks, and we do not track you across other companies' apps or websites.
The Website uses only first-party cookies, set by tastyer.com itself:
t_accessandt_refresh— keep you signed in to the web app. Strictly necessary; set only when you log in; they last 30 minutes and 7 days.tst_aid— a random identifier that lets us count visits and connect the product events described in section 2. It contains nothing about you; it lasts one year.tst_ft— your first visit's campaign tags, referring website and landing page (see “Install & Campaign Attribution”). It lasts 30 days.
The Website also keeps a few short-lived values in your browser's session storage (for example, so a visit is counted only once); these are erased when you close the tab. You can delete cookies at any time in your browser settings; the Website keeps working, but you will be signed out.
9. The Website & Launch Waitlist
This section covers the website (tastyer.com) itself, separately from the App. Besides the product events and cookies described above, the website uses privacy-friendly, first-party analytics (no cross-site advertising cookies) to understand which pages work.
If you join the launch waitlist, we store two things: your email address and which button or page you signed up from (for example “hero” or “pricing”), purely so we can see which explanations resonate. We use your email for exactly one thing: to email you once, when Tastyer launches on the App Store. We never sell it or share it with third parties.
You can remove yourself at any time at tastyer.com/unsubscribe, or by emailing privacy@tastyer.com — we delete your address immediately. The waitlist is always optional; the site works fine without it. To limit spam and abuse of the form we briefly inspect your IP address for rate-limiting only; it is not stored.
10. Children's Privacy
The App is not intended for children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us to have it removed.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes through the App. Continued use after changes constitutes acceptance of the updated policy.
12. Contact
For privacy-related questions or to exercise your data rights:
Email: privacy@tastyer.com
